
Almost no company thinks about its disaster recovery plan until it suffers a real outage — and by then it is too late to improvise. Business continuity does not depend on having backups; it depends on knowing exactly how long it takes to get back online and how much data the business can afford to lose.
RTO and RPO: the two numbers that matter
RTO (Recovery Time Objective) is the maximum tolerable time without service before the impact becomes unmanageable. RPO (Recovery Point Objective) is how much data the business can afford to lose, measured in time — if the RPO is one hour, a daily backup falls short. Defining these two numbers for each critical system is the first step, and most companies have never written them down.
The drill almost no one runs
Having backups is not the same as knowing how to restore them under pressure. A recovery drill — turning off a system and timing how long it actually takes to bring it back — is the only way to know if the plan works, and it usually reveals problems that never show up on paper: expired credentials, forgotten dependencies, manual steps no one documented.
